Permissions

Three permission levels control what each team member can do. You set them per person, and someone can hold a different level on a different project.

Owner

Everything. Edit and publish content, view analytics, manage the team, connect a domain, change billing, and every setting.

You can have more than one owner, and it is worth having two. An owner is the only person who can add another owner, so if the single owner loses access, getting back in goes through Helm rather than through your own team — a support request instead of something you can sort out between yourselves. A second owner keeps it in your hands.

Editor

The day-to-day level: edit content, publish it, upload media, view analytics, edit SEO, manage bookings and orders.

What an editor cannot do is anything that changes the business rather than the site — adding or removing team members, billing and plan changes, buying or connecting a domain, connecting Google Search Console, or turning modules on and off.

If you are wondering which level someone needs, the question is usually "should this person be able to spend money or change who has access?" If no, editor is enough.

Viewer

Read-only. They see the content and the analytics and can change nothing.

This is not a weak editor — it is enforced separately. Viewer does not appear anywhere in the list of levels allowed to write, so there is no path through the system where a viewer's change is accepted. It fails at the door rather than being checked and refused.

Useful for an accountant who needs the numbers, a client's colleague who wants to look, or anyone you would rather not have to trust with a publish button.

Changing someone's permission

Open Team from the menu and change the Permission dropdown next to their name. Only an owner can do this.

It takes effect immediately, on their next click. Helm checks a person's current permission on every single request rather than trusting the session they signed in with, so demoting or removing someone does not wait for them to log out and back in. If you have just realised the wrong person has access, changing this is enough — you do not also need to reset anything.

Removing someone

Remove them from the Team page. Their access ends the same way and just as fast. Anything they published stays published; permissions control what someone can do next, not what already happened.